fix(deps): refresh lockfile to clear 4 transitive advisories - #117
Merged
Merged
Conversation
All four findings were transitive, with zero direct dependencies
implicated, so no package.json range needed to change. Each was a stale
lockfile entry rather than a genuinely new vulnerability:
- brace-expansion 1.1.18 / 5.0.9 (high) via minimatch under
eslint-plugin-jsx-a11y, @microsoft/api-extractor and
eslint-plugin-import-x. Covers the DoS advisories: exponential
expansion of non-expanding {} groups, unbounded expansion length,
quadratic-time `{a},b}` rewrite and uncontrolled recursion on nested
brace groups. Now 5.0.12.
- fast-uri 3.1.6 (high) via ajv 8.20.0 under @hookform/resolvers and
@microsoft/tsdoc-config. ajv already declares ^3.0.1, which admits the
patched 3.1.8; the lockfile had not moved. Covers the authority
injection and unclosed-bracket host confusion.
- js-yaml 4.3.1 / 3.15.1 (high) via @changesets/cli, @changesets/parse
and read-yaml-file. Now 4.3.2 / 3.15.2, which is where the CVE-2026-59870
!!omap quadratic-CPU fix and the maxTotalMergeKeys fix actually land.
- esbuild 0.27.7 (low) via tsup. Now 0.28.1, clearing the 0.27.3 - 0.28.0
Windows dev-server arbitrary file read.
A non-force `npm audit fix` moved all four inside ranges their parents
already declared, and left package.json byte-identical.
npm audit: 4 -> 0 (3 high, 1 low -> 0).
Verified, all exit 0: npm install, typecheck, build, lint, test:runtime
(12 files / 89 tests), test:coverage (100% stmts, 96.37% branches,
unchanged thresholds), format:check, audit:source, registry:check,
storybook:check, bundle:check, test:contracts (29 tests), pack:check,
package:lint, api:check.
No engines inconsistency: package.json is untouched, so the engines
">=20" pin and the Node 22/24 CI matrix are unaffected.
Not run, needs a browser or a Storybook server: test:e2e, test:design,
storybook:build, storybook:typecheck.
Reported, not taken - all majors: vitest 5.0.2 and @vitest/coverage-v8
5.0.2 (repo is on 4.1.11, already outside the vulnerable 2.1.0-beta.1 -
4.1.10 range), typescript 7.0.2, recharts 3.10.1 (the 2.x branch is
deprecated but not vulnerable), zod 4.6.5, @changesets/cli 3.0.3.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Part of a dependency baseline sweep across the mivabyte org.
Audit: 4 -> 0 (3 high, 1 low)
package.jsonis unchanged in this PR. All four advisories were stalelockfile entries whose parents already declared patched ranges — a plain
lockfile refresh was sufficient.
package-lock.jsonis the only modified file.Verification (Node 24.21.0, wiped node_modules)
Full gate, every step exit 0:
Coverage thresholds were not changed — nothing was weakened to get green.
Not run:
test:e2e,test:design,storybook:build,storybook:typecheck— these need a browser or a running Storybook server.Left alone
All remaining outdated packages are majors: vitest 5.0.2,
@vitest/coverage-v8 5.0.2, typescript 7.0.2, recharts 3.10.1, zod 4.6.5,
@changesets/cli 3.0.3.
Why this repo got the most conservative treatment
uiis the shared@mivabyte/uidesign-system package.ui-showcaseconsumesit via
github:mivabyte/ui#main, so a brokenuibreaks every downstreamconsumer. Hence: no manifest edits, no version bumps, lockfile only, and the
full gate run rather than just build.